These SaaS Use Restrictions are incorporated into the Accounting Orbit Terms of Use. Capitalized terms have the meanings given in the Terms of Use. For purposes of Sections 1 through 10:
1. Definitions
1.1 Provider
“Provider” means Accounting Orbit, together with its affiliates, licensors, service providers, successors, and permitted, assigns, where applicable.
1.2 Service
“Service” means all, products, services, technology, and resources made available by or on behalf of the Provider, including:
- (a) the Provider’s software-as-a-service platform;
- (b) public and nonpublic websites and webpages;
- (c) mobile, desktop, and web applications;
- (d) demonstrations, trials, preview environments, test environments, beta features, and prerelease features;
- (e) APIs, integrations, databases, documentation, and developer resources;
- (f) software, systems, servers, networks, interfaces, workflows, designs, features, functionality, content, data, metadata, and outputs; and
- (g) all related, technology, products, services, and materials.
The Service includes both authenticated and unauthenticated portions of the Provider’s websites, applications, and systems.
1.3 User
“User,” “you,” or “your” means any individual or entity that accesses, views, browses, inspects, evaluates, monitors, registers for purchases, or uses any portion of the Service, to the extent that the applicable agreement is legally binding upon that individual or entity.
The term, includes, as applicable:
- (a) visitors and prospective customers;
- (b) customers, subscribers, and Account Holders;
- (c) authorized account users and persons who receive delegated or shared access;
- (d) employees, officers, contractors, consultants, agents, and representatives;
- (e) competitors and persons acting, for at the direction of or for the benefit of competitors;
- (f) persons accessing the Service with or without an account; and
- (g) persons acting directly or indirectly for through, at the direction of or for the benefit of another individual or entity.
Where an individual accesses or uses the Service for through, at the direction of or on behalf of an organization, both the individual and the organization are Users.
The organization is responsible for the acts and omissions of each individual whom it authorizes, enables, permits, or knowingly allows to access or use the Service. Each individual also remains separately and independently responsible for that individual’s own conduct.
1.4 Account Holder
“Account Holder” means the individual or entity that creates, purchases, owns, controls, administers, or is identified as the holder of an account, subscription, license, or other right to access the Service.
1.5 Confidential Information
“Confidential Information” means all, nonpublic, proprietary, or confidential information disclosed or made available by or on behalf of the Provider, whether disclosed, orally, visually, electronically, in writing, through access to the Service, or in any other form.
Confidential Information includes:
- (a) source code, object code, algorithms, models, model configurations, model parameters, training methods, data structures, software architecture, system designs, technical specifications, methods, processes, formulas, prototypes, and nonpublic functionality;
- (b) nonpublic documentation, product plans, development plans, roadmaps, research, testing information, performance information, analytics, and unreleased features;
- (c) security measures, authentication methods, vulnerability information, penetration-testing results, incident information, access controls, infrastructure information, system configurations, and business-continuity or disaster-recovery procedures;
- (d) pricing strategies, nonpublic pricing, financial information, forecasts, budgets, sales information, marketing strategies, business plans, vendor information, contractual terms, and commercial methods;
- (e) customer, prospect, employee, contractor, supplier, licensor, and business-partner, information, including customer lists and nonpublic usage information;
- (f) trade secrets and information protected by applicable intellectual-property, confidentiality, privacy, or unfair-competition laws; and
- (g) other nonpublic information identified as confidential or proprietary, or that a reasonable person would understand to be confidential based on the nature of the information or the circumstances of its disclosure.
Confidential Information does not include information that the User can demonstrate through contemporaneous written records:
- (i) was lawfully known to the User without a duty of confidentiality before disclosure by the Provider;
- (ii) becomes publicly available through no breach of the applicable agreement and no wrongful act or omission by the User or anyone acting on the User’s behalf;
- (iii) is lawfully received from a third party without breach of a confidentiality obligation;
- (iv) is independently developed by the User without accessing, using, or relying upon the Provider’s Confidential Information; or
- (v) is expressly designated by the Provider in writing as nonconfidential.
A combination, compilation, arrangement, or organization of information shall not be considered public or nonconfidential merely because individual elements are publicly available, if the combination, compilation, arrangement, or organization itself is nonpublic and confidential.
1.6 Applicable Agreement
“Applicable Agreement” means the Terms of Use, together with any subscription, agreement, order form, license agreement, service agreement, acceptable-use policy, security policy, or other written agreement governing access to or use of the Service.
2. Acceptance and Limited Right to Use the Service
2.1 Acceptance
A User agrees to be legally bound by the applicable agreement when the User:
- (a) clicks a button stating that the User accepts or agrees to the applicable agreement;
- (b) checks a box stating that the User has read and agrees to the applicable agreement;
- (c) creates an account after being presented with conspicuous notice of the applicable agreement;
- (d) accepts an invitation to access an account or the Service after being presented with conspicuous notice of the applicable agreement;
- (e) signs in or accesses a shared or delegated account after being presented with conspicuous notice of the applicable agreement; or
- (f) otherwise affirmatively manifests agreement to the applicable agreement.
Where legally sufficient notice is presented in connection with access to or use of the Service, continued access or use following that notice constitutes acceptance to the extent permitted by applicable law.
An individual accepting the applicable agreement for an organization represents and warrants that the individual has the authority to bind that organization.
If the individual lacks that authority, the individual may not accept the applicable agreement or access or use the Service on behalf of the organization.
2.2 Limited License
Subject to the User’s continuing compliance with the applicable agreement, the Provider grants the User a limited, revocable, nonexclusive, nontransferable, and nonsublicensable right to access and use the Service solely:
- (a) during the applicable subscription or authorized access period;
- (b) for the User’s internal and authorized purposes;
- (c) within the scope of the applicable subscription plan, order form, or written authorization; and
- (d) in compliance with all applicable documentation, usage limits, and laws.
2.3 Revocability
The User’s access rights are conditional and may be restricted, suspended, disabled, or revoked as provided in the applicable agreement, including Section 10.
No payment, subscription, registration, account creation, invitation, or prior access creates an irrevocable or perpetual right to access or use the Service.
2.4 No Implied Rights
The Provider and its licensors retain all rights not expressly granted to the User.
No license or right is granted by implication, estoppel, exhaustion, course of dealing, or otherwise.
3. Confidentiality
3.1 Limited Use
The User shall use the Provider’s Confidential Information solely as necessary to exercise the limited rights expressly granted under the applicable agreement and for no other purpose.
The User shall not use Confidential Information:
- (a) for the User’s commercial benefit except as expressly authorized by the applicable agreement;
- (b) for the benefit of a third party;
- (c) to compete with the Provider or assist another person in competing with the Provider;
- (d) to develop, improve, train, test, validate, market, support, finance, or operate a competing or substitute product, service, model, system, or technology; or
- (e) for an unlawful, unauthorized, or prohibited purpose.
The User shall not copy, reproduce, download, extract, summarize, modify, translate, create derivative materials from or otherwise use Confidential Information except to the minimum extent necessary for an expressly authorized use of the Service.
3.2 Nondisclosure
The User shall not disclose or make Confidential Information available to another person or entity except to the User’s employees, officers, contractors, professional advisers, and agents who:
- (a) have a legitimate need to know the information for an authorized purpose;
- (b) have been informed of its confidential nature; and
- (c) are bound by written confidentiality and use restrictions at least as protective as those contained in the applicable agreement.
The User is responsible for any act or omission of its representatives that would constitute a breach of this Section if committed by the User.
The User shall not disclose Confidential Information to a competitor of the Provider without the Provider’s prior written consent.
3.3 Safeguarding Confidential Information
The User shall protect Confidential Information using at least the same degree of care it uses to protect its own information of similar sensitivity and importance, but in no event less than reasonable care.
The User shall maintain reasonable administrative, technical, organizational, and physical safeguards designed to prevent:
- (a) unauthorized access, acquisition, use, copying, disclosure, alteration, loss, or destruction;
- (b) accidental or unlawful transmission or distribution;
- (c) compromise of credentials, systems, devices, or accounts through which Confidential Information may be accessed; and
- (d) other unauthorized or prohibited activity involving Confidential Information.
The User shall limit access to authorized persons and promptly revoke such access when it is no longer required.
3.4 Unauthorized Access or Disclosure
The User shall promptly notify the Provider after discovering or reasonably suspecting:
- (a) unauthorized access to acquisition of use of or disclosure of Confidential Information;
- (b) loss or compromise of Confidential Information;
- (c) loss, theft, or compromise of a device, credential, token, account, or system containing or providing access to Confidential Information; or
- (d) another violation of this Section.
The User shall:
- (i) take immediate reasonable steps to contain and remediate the incident;
- (ii) preserve relevant evidence;
- (iii) reasonably cooperate with the Provider’s investigation, remediation, notification, and enforcement efforts; and
- (iv) refrain from making a public statement identifying the Provider in connection with the incident without the Provider’s prior written approval, except where disclosure is legally required.
Notification does not relieve the User of liability arising from the incident or underlying breach.
3.5 Legally Required Disclosure
If the User or its representative is legally compelled to disclose Confidential Information, the User shall to the extent legally permitted:
- (a) provide prompt written notice to the Provider before disclosure;
- (b) provide reasonable details concerning the requested disclosure;
- (c) reasonably cooperate, at the Provider’s expense, with efforts to seek a protective, order, confidential treatment, or other appropriate remedy; and
- (d) disclose only the minimum portion legally required.
A legally compelled disclosure does not authorize use or disclosure for another purpose.
3.6 Ownership
All Confidential Information remains the exclusive property of the Provider or its licensors.
Disclosure of Confidential Information does not transfer ownership or grant a license, intellectual-property right, or other right except as expressly stated in the applicable agreement.
3.7 Return and Destruction
Upon the Provider’s request or the suspension, revocation, expiration, cancellation, or termination of the User’s account, subscription, license, access rights, or applicable agreement, the User shall promptly:
- (a) cease accessing and using Confidential Information;
- (b) return or permanently delete and destroy all Confidential Information in the User’s possession, custody, or control;
- (c) permanently delete or destroy all copies, extracts, summaries, analyses, notes, datasets, models, derivative materials, and records containing or reflecting Confidential Information;
- (d) require its representatives to do the same; and
- (e) upon request, provide written certification signed by an authorized representative confirming compliance.
The User may retain information only to the extent required by law or automatically preserved in routine backup systems that cannot reasonably be isolated and deleted, provided that:
- (i) the retained information remains protected under this Section;
- (ii) it is not accessed or used except as legally required or for routine disaster recovery;
- (iii) it is deleted through the ordinary backup-retention cycle; and
- (iv) retention does not permit continued commercial, competitive, operational, or other use.
3.8 Independent Development
Nothing in this Section prohibits independent development without accessing, using, disclosing, relying, upon, or deriving benefit from Confidential Information.
The User bears the burden of demonstrating independent development through contemporaneous written records.
Independent development does not authorize activity otherwise prohibited by Sections 4 through, 10, including competitive intelligence gathered from public portions of the Service.
3.9 Equitable Relief
The User acknowledges that actual or threatened unauthorized use or disclosure of Confidential Information may cause immediate and irreparable harm for which monetary damages alone may be inadequate.
The Provider may seek, temporary, preliminary, permanent, emergency, or other equitable relief in addition to damages and all other available remedies.
To the maximum extent permitted by applicable law, the User waives any requirement that the Provider post a bond or other security in connection with a request for such relief.
If a court nevertheless requires security, its amount and terms shall be determined by the court under applicable law.
3.10 Survival
The obligations in this Section survive, expiration, cancellation, suspension, revocation, or termination:
- (a) for trade secrets, for as long as the information remains a trade secret under applicable law; and
- (b) for other Confidential Information, for five years following the applicable disclosure or any longer period stated elsewhere in the applicable agreement.
Termination, return, deletion, or destruction does not release the User from liability for a prior violation.
4. Automated Access, Scraping, Crawling, and Data Extraction
The User shall not directly or indirectly, use a robot, bot, spider, crawler, scraper, script, data-mining, tool, automated, agent, artificial-intelligence, agent, browser-automation tool, or other automated process to:
- (a) access, search, query, monitor, navigate, or interact with the Service;
- (b) copy, download, collect, harvest, extract, index, reproduce, aggregate, capture, store, or otherwise obtain data, content, output, metadata, records, listings, or other information from the Service;
- (c) create or maintain a database, directory, dataset, index, cache, archive, repository, or collection derived from or based upon the Service;
- (d) systematically retrieve data or materials, whether for commercial, research, educational, personal, or other purposes;
- (e) circumvent an access limit, rate limit, usage restriction, technical control, or other limitation imposed by the Provider; or
- (f) assist, enable, direct, encourage, finance, or permit another person to engage in prohibited activity.
This Section does not prohibit automated access through an API, integration, export function, or other automated functionality expressly authorized in writing by the Provider, provided that access complies with all applicable documentation, license terms, usage limits, security requirements, and written authorization.
The Provider may modify, restrict, suspend, or revoke authorization for automated access in accordance with the applicable agreement.
5. Reverse Engineering and Technical Restrictions
Except to the limited extent expressly prohibited by applicable law, the User shall not, directly or indirectly:
- (a) reverse engineer, decompile, disassemble, decode, decrypt, translate, reconstruct, or otherwise attempt to discover, obtain, derive, or determine source code, object code, algorithms, data structures, architecture, models, model parameters, methods, logic, design, underlying ideas, trade secrets, or nonpublic technical components of the Service;
- (b) attempt to determine how a feature, model, algorithm, scoring, process, recommendation, system, authentication, mechanism, security, measure, access, control, or internal process operates;
- (c) derive or attempt to derive the composition, structure, organization, operation, architecture, training, methodology, or underlying technology of the Service;
- (d) access or use the Service to identify, analyze, exploit, or reproduce a technical, limitation, vulnerability, error, design feature, or nonpublic functionality;
- (e) translate, convert, or transform a portion of the Service into human-readable, source-code, or alternative form;
- (f) access or use a nonpublic API, endpoint, administrative interface, developer tool, internal system, or other technical resource without written authorization; or
- (g) assist, enable, direct, encourage, finance, or permit another person to engage in prohibited activity.
Where applicable law grants a nonwaivable right to conduct limited reverse engineering or interoperability, activity, the User must first provide written notice to the Provider and request the information reasonably necessary to accomplish the legally permitted purpose, unless the law expressly prohibits such a notice requirement.
Any legally permitted activity must be limited strictly to the minimum extent necessary.
6. Modification, Copying, and Derivative Works
Except as expressly authorized in a written agreement signed by the Provider, the User shall not directly or indirectly:
- (a) modify, adapt, alter, translate, transform, copy, reproduce, republish, distribute, sublicense, sell, resell, rent, lease, display, transmit, frame, mirror, or create derivative works based upon the Service;
- (b) create a modification, enhancement, extension, adaptation, translation, add-on plug-in or derivative product based upon or incorporating the Service;
- (c) remove, obscure, alter, disable, or conceal a copyright, trademark, patent, attribution, proprietary-rights notice, digital watermark, access control, or other notice;
- (d) combine, incorporate, embed, integrate, or use the Service in another, product, service, application, platform, dataset, model, database, or system except through an expressly approved integration;
- (e) reproduce, copy, imitate, or materially replicate the Service’s design, appearance, user interface, user experience, workflow, organization, structure, architecture, outputs, or functionality;
- (f) separate a component of the Service for independent, use, licensing, distribution, commercialization, or exploitation;
- (g) make the Service available through a service bureau, time-sharing arrangement, managed service, hosted offering, sublicense, resale arrangement, or similar means unless expressly authorized; or
- (h) assist, enable, direct, encourage, finance, or permit another person to engage in prohibited activity.
7. Competitive Intelligence, Competitive Use, and AI Training
The User shall not directly or indirectly, access, view, browse, inspect, evaluate, monitor, study, test, record, document, or use the Service for a prohibited purpose under this Section.
This restriction applies whether the activity is conducted:
- (a) manually or automatically;
- (b) through an account or without an account;
- (c) through public or nonpublic portions of the Service;
- (d) directly or through an employee, contractor, consultant, agent, customer, researcher, Account Holder, account user, or other intermediary; or
- (e) by any other means.
The User shall not access or use the Service or related materials for the purpose of:
- (a) conducting or gathering competitive intelligence, including identifying, documenting, analyzing, comparing, mapping, or evaluating the Service’s features, pricing, functionality, design, user experience, workflows, processes, architecture, outputs, business methods, customer experience, or commercial strategy for the benefit of a competitor or in connection with a competing or substitute product or service;
- (b) developing, designing, improving, testing, validating, marketing, operating, supporting, financing, supplying, or providing a product or service that competes, with substitutes for or is materially similar to the Service;
- (c) reproducing, replicating, substituting for or materially imitating the Service’s functionality, features, outputs, user experience, workflows, structure, architecture, design, methods, or business processes;
- (d) conducting benchmarking, performance testing, comparison testing, reverse comparison, or evaluation intended for publication, commercial, use, product, development, investment, analysis, procurement, analysis, or competitive development without the Provider’s prior written authorization;
- (e) collecting, recording, photographing, screenshotting, screen-recording, capturing, documenting, or using information concerning the Service to assist a person in designing, developing, enhancing, training, marketing, supplying, financing, or operating a competing or substitute product or service;
- (f) using the Service, data obtained from the Service, or content or output, generated, displayed, transmitted, or made available by the Service to train, pre-train, fine-tune, retrain, improve, evaluate, validate, benchmark, test, distill, ground, augment, or otherwise develop an artificial-intelligence model, machine-learning algorithm, large language, model, foundation model, generative model, automated decision, system, or similar technology;
- (g) using the Service or its outputs as training, data, validation data, evaluation data, synthetic data, retrieval-augmentation data, model inputs, prompts, labels, embeddings, model weights, or other materials used to develop or operate an artificial-intelligence or machine-learning system;
- (h) using output from the Service to reproduce, approximate, imitate, distill, extract, or infer the behavior, capabilities, architecture, parameters, training methods, or functionality of the Service or a model incorporated into the Service; or
- (i) assisting, enabling, directing, encouraging, financing, or permitting another person to engage in prohibited activity.
These restrictions apply regardless of whether the relevant portion of the Service is:
- (i) publicly accessible;
- (ii) password protected;
- (iii) provided through a free or paid account; or
- (iv) made available through a demonstration, trial, preview, test, or beta offering.
An activity prohibited by this Section may be conducted only when expressly authorized in a written agreement signed by the Provider.
Nothing in this Section prohibits independent development of a product or service, provided that the development does not involve:
- (A) use of the Provider’s Confidential Information;
- (B) access to or use of public or nonpublic portions of the Service for a purpose prohibited by this Section;
- (C) use of data, content, output, documentation, or materials obtained from the Service for a prohibited purpose; or
- (D) information obtained in violation of the applicable agreement or applicable law.
8. Account Security, Account Sharing, and Unauthorized Access
8.1 Account Security
The Account Holder and each account user shall maintain the confidentiality and security of all passwords, credentials, access tokens, API keys, devices, sessions, and other means of accessing the Service.
The Account Holder shall:
- (a) provide complete and accurate account information;
- (b) keep account and contact information current;
- (c) use reasonable safeguards to protect its account and credentials;
- (d) promptly revoke access that is no longer required;
- (e) promptly change or disable credentials that are lost, disclosed, or reasonably suspected of compromise; and
- (f) promptly notify the Provider after discovering or reasonably suspecting unauthorized or prohibited access.
8.2 Account Sharing, Delegated Access, and Downstream Access
The Account Holder shall not share, transfer, lend, sublicense, sell, disclose, or otherwise provide another person or entity with access to the Account Holder’s account, credentials, subscription, license, or access rights except to the extent expressly permitted by the applicable subscription plan or authorized in writing by the Provider.
For purposes of this Agreement, “Downstream User” means any individual or entity that directly or indirectly receives, obtains, exercises, or benefits from access to the Service through another User, Account Holder, Downstream User, organization, credential, device, session, invitation, link, token, integration, or other access mechanism.
A Downstream User includes any person or entity that receives access through one or more intermediate persons or entities, regardless of how many times the access is shared, transferred, delegated, disclosed, enabled, or otherwise passed from one person or entity to another. Each individual and entity in the access chain is a User and may be held responsible under the applicable agreement.
No User may provide, enable, delegate, transfer, disclose, sublicense, or otherwise make available any account, credential, subscription, license, access right, data, output, or other Service access to a third party unless expressly authorized by the Provider.
8.3 Acceptance and Independent Responsibility of Each Downstream User
Each Downstream User who accesses or uses the Service after receiving conspicuous notice of the applicable agreement is independently bound by the applicable agreement.
Each Downstream User is separately responsible for that Downstream User’s own:
- (a) access to and use of the Service;
- (b) acts and omissions;
- (c) violations of the applicable agreement;
- (d) sharing, transfer, delegation, disclosure, or further distribution of access;
- (e) acquisition, use, copying, disclosure, retention, transfer, or distribution of data, outputs, credentials, or Confidential Information; and
- (f) assistance, direction, authorization, facilitation, financing, or encouragement of prohibited activity.
A Downstream User may not avoid responsibility by asserting that:
- (i) access was originally obtained from another person or entity;
- (ii) the Account Holder or another User authorized or requested the access;
- (iii) the Downstream User did not create or purchase the original account;
- (iv) access passed through multiple persons or entities before reaching the Downstream User;
- (v) another person physically performed the prohibited act; or
- (vi) the Downstream User acted for through, at the direction of or on behalf of a company, employer, customer, contractor, affiliate, or other organization.
8.4 Responsibility for Providing or Enabling Downstream Access
Each User is responsible for access that the User directly or indirectly:
- (a) shares, transfers, delegates, sublicenses, sells, discloses, distributes, or provides;
- (b) authorizes, invites, approves, enables, facilitates, directs, encourages, or finances;
- (c) permits through the use of a shared password, credential, token, link, device, session, integration, or other access mechanism;
- (d) knowingly allows to continue;
- (e) fails to revoke or disable after discovering or reasonably suspecting that another person or entity has obtained access; or
- (f) causes or contributes to through a violation of the User’s account-security obligations.
A User who provides or enables access to another person or entity is also responsible for any additional access that the receiving person or entity subsequently, provides, enables, delegates, transfers, or distributes, to the extent that such downstream access was authorized, knowingly, permitted, facilitated, reasonably foreseeable, or caused by the original User’s conduct.
8.5 Organizational and Company Responsibility
If access is provided, to used by or exercised for the benefit of a company, partnership, association, agency, institution, employer, customer, affiliate, contractor, or other organization, that organization is a User and is responsible for:
- (a) access to and use of the Service by its employees, officers, owners, directors, contractors, consultants, agents, representatives, affiliates, and other persons acting for or on its behalf;
- (b) access occurring through credentials, devices, networks, systems, domains, email addresses, integrations, or accounts that the organization owns, controls, administers, funds, supplies, or permits;
- (c) any person or entity to whom the organization directly or indirectly provides, enables, delegates, or permits access;
- (d) violations committed for the organization’s benefit, at its direction, with its knowledge, or through access the organization provided or controlled; and
- (e) downstream sharing or distribution of access by persons or entities within its access chain.
Each individual who accesses or uses the Service for or on behalf of an organization remains independently responsible for that individual’s own conduct. The organization may not avoid responsibility by asserting that the prohibited activity was performed by an employee, contractor, consultant, affiliate, agent, intermediary, or other third party.
8.6 Joint and Several Responsibility Across the Access Chain
To the maximum extent permitted by applicable law, every Account Holder, User, Downstream User, and organization that shares, transfers, delegates, provides, enables, facilitates, knowingly permits, or materially contributes to access shall be jointly and severally liable for violations committed through or in connection with that access chain.
The Provider may investigate, enforce, restrict, suspend, terminate, assert claims, against or pursue remedies from any party in the access chain and is not required to pursue parties in any particular order or exhaust remedies against one before pursuing another.
A payment, settlement, judgment, suspension, termination, release, or other remedy involving one responsible party does not release another responsible party unless the Provider expressly agrees to that release in a written document signed by an authorized representative of the Provider.
8.7 Unauthorized Credential-Theft Exception
A person or entity shall not be responsible solely because an unknown third party obtained access through credential, theft, hacking, or another security incident that the person or entity did not authorize, knowingly, permit, cause, facilitate, or negligently contribute to provided that the person or entity:
- (a) complied with all applicable account-security obligations;
- (b) did not voluntarily disclose or improperly safeguard the affected credentials;
- (c) promptly notified the Provider after discovering or reasonably suspecting the unauthorized access;
- (d) promptly changed, disabled, or secured the affected credentials and access mechanisms; and
- (e) reasonably cooperated with the Provider’s investigation, containment, remediation, and enforcement efforts.
This exception does not apply where the person or entity voluntarily provided access to another party and that party subsequently, shared, transferred, delegated, or distributed the access.
9. System Interference, Malicious Activity, and Vulnerability Testing
The User shall not directly or indirectly:
- (a) interfere with disrupt, damage, overload, flood, degrade, impair, disable, or adversely affect the operation, availability, performance, integrity, stability, reliability, or security of the Service or a related, server, database, system, application, device, or network;
- (b) introduce, upload, transmit, distribute, install, store, or execute a virus, worm, Trojan horse, ransomware, spyware, malware, logic bomb, malicious code, corrupted data, harmful file, denial-of-service traffic, or other destructive or disruptive material;
- (c) launch, participate, in facilitate, or assist with a denial-of-service attack, distributed denial-of-service attack, traffic flood, resource-exhaustion attack, credential-stuffing attack, password-spraying attack, brute-force attack, automated account-creation, activity, or similar conduct;
- (d) scan, probe, test, audit, assess, analyze, or monitor the vulnerability, configuration, security, availability, or performance of the Service or a related system or network;
- (e) perform or attempt penetration testing, vulnerability testing, load testing, stress testing, security research, red-team activity, exploit testing, or other technical testing without the Provider’s prior written authorization;
- (f) attempt to gain unauthorized access to a system, network, account, credential, data, software, device, or environment;
- (g) intercept, monitor, capture, redirect, alter, block, or interfere with communications, traffic, data, requests, responses, or transmissions to or from the Service;
- (h) interfere with another person’s authorized access to or use of the Service;
- (i) exploit, publicize, publish, sell, disclose, transfer, or use a suspected or confirmed, vulnerability, except solely through and in accordance with an authorized vulnerability-disclosure or security-testing program described below in this Section 9;
- (j) attempt to evade detection, logging, monitoring, security controls, account enforcement, or incident-response measures;
- (k) use the Service to facilitate unlawful access to or interference with a third-party system, service, network, account or data; or
- (l) assist, enable, direct, encourage, finance, or permit another person to engage in prohibited activity.
Authorized security research may be conducted only pursuant to the Provider’s prior written authorization and in strict compliance with all scope limitations, testing procedures, disclosure, requirements, time, limitations, confidentiality, obligations, data-handling requirements, and other conditions imposed by the Provider.
The User shall promptly notify the Provider at [email protected] after discovering an actual or suspected vulnerability, unauthorized, access, security, incident, or misuse affecting the Service. Providing notice does not authorize continued, testing, accessing, exploiting, or disclosing.
10. Material Breach; Revocation, Suspension, Termination, and Legal Remedies
Any actual, attempted, threatened, assisted, enabled, directed, encouraged, financed, or facilitated violation of Sections 3 through 9 constitutes a material breach of the applicable agreement.
10.1 Right to Restrict, Suspend, and Revoke Use
Upon an actual or reasonably suspected violation, the Provider may to the maximum extent permitted by applicable law and without limiting another right or remedy:
- (a) investigate the suspected violation;
- (b) preserve relevant, records, logs, communications, account information, device information, access information, and evidence;
- (c) restrict, limit, disable, suspend, or terminate the User’s account or access;
- (d) suspend or revoke the User’s limited right and license to access or use all or part of the Service;
- (e) revoke or disable a password, credential, token, API key, integration, session, device, authorization, or other access mechanism;
- (f) block or restrict devices, accounts, network addresses, domains, integrations, or other access methods;
- (g) terminate the applicable subscription, order, license, or agreement, including without an opportunity to cure where permitted by applicable law and the applicable agreement;
- (h) refuse to create, approve, reactivate, or provide a current or future, account, subscription, license, or access right;
- (i) require the User to cease prohibited activity; and
- (j) take other reasonable action necessary to protect the Service Provider, customers, licensors, service providers, or affected persons.
Unless otherwise required by applicable law or the applicable agreement, the Provider may act immediately and without prior notice where it reasonably determines that immediate action is necessary.
10.2, Return, Deletion, and Preservation of Materials
The Provider may require the User to:
- (a) return, permanently, delete, destroy, surrender, or cease using data, content, output, software, documentation, Confidential Information, credentials, copies, extracts, models, datasets, derivative materials, or other items obtained, created, or maintained through prohibited conduct;
- (b) identify each person or entity to whom such materials were disclosed or made available;
- (c) take reasonable steps to obtain the return, deletion, destruction, or surrender of materials disclosed to third parties; and
- (d) provide written certification signed by an authorized representative confirming compliance.
Nothing in this Section requires the Provider to return or delete evidence reasonably preserved for security, fraud, prevention, investigation, dispute resolution, regulatory compliance, enforcement, or legal proceedings.
10.3 Shared Accounts, Downstream Access, and Multiple Responsible Parties
Where two or more Account Holders, Users, Downstream Users, organizations, or other persons or entities share responsibility under Section, 8, the Provider may pursue any one or more of them, jointly or separately, at any point in the access chain.
Restricting, suspending, revoking, terminating, settling with releasing, or obtaining relief against one responsible party does not release another responsible party unless the Provider expressly agrees otherwise in a written document signed by an authorized representative of the Provider.
10.4 Preservation of Claims and Right to Pursue Legal Action
Any restriction, suspension, revocation, disablement, or termination of the User’s account, license, subscription, agreement, or access is in addition to and not in place of any other right or remedy available to the Provider. Such action shall not waive, limit, release, satisfy, discharge, settle, or otherwise affect the User’s liability, the Provider’s, claims, or the Provider’s right to investigate, preserve, evidence, or commence or continue legal proceedings.
The Provider expressly retains and reserves the right to commence, pursue, maintain, or continue any lawsuit, arbitration, claim, investigation, administrative, proceeding, law-enforcement referral, or other legal action, before during or after restricting, suspending, revoking, disabling, or terminating access.
10.5 Damages and Other Remedies
To the extent permitted by applicable law and the applicable agreement, the Provider may recover actual, compensatory, statutory, incidental, consequential, exemplary, punitive, or other damages; restitution, disgorgement, or unjust-enrichment damages; reasonable attorneys’ fees, expert, fees, forensic, expenses, investigation, costs, remediation expenses, and enforcement expenses; an accounting of revenue, benefits, data, products, models, or intellectual property derived from prohibited conduct; specific performance; and all other remedies available under the applicable agreement, at law, or in equity.
Nothing in this Section permits more than one recovery for the same damages.
10.6 Injunctive and Equitable Relief
The User acknowledges that an actual or threatened violation of Sections 3 through 9 may cause immediate and irreparable harm for which monetary damages alone may be inadequate. The Provider may seek, temporary, preliminary, permanent, emergency, or other injunctive or equitable relief, including a temporary restraining order, injunction, specific performance, equitable, accounting, restitution, disgorgement, and preservation or recovery of evidence or property, without proving actual damages or posting bond to the extent permitted by law. Nothing prevents the Provider from seeking temporary or emergency equitable relief in any court having jurisdiction.
10.7 Notifications and Cooperation
Where permitted by applicable law, the Provider may notify affected customers, business partners, licensors, service providers, payment providers, insurers, regulators, law-enforcement authorities, or other appropriate parties if reasonably necessary. The User shall reasonably cooperate with the Provider’s investigation and remediation of a suspected violation. Nothing requires the User to waive a nonwaivable right or legal privilege.
10.8 No Waiver; Cumulative Remedies
The Provider’s pursuit or receipt of any relief does not prevent the Provider from seeking monetary damages or exercising another right or remedy. The Provider’s failure or delay in investigating, enforcing, or exercising a right does not constitute approval, authorization, or waiver. A waiver is effective only if expressly stated in a written document signed by an authorized representative of the Provider. All rights and remedies are cumulative and not exclusive.
10.9 Survival
Sections 1 and 3 through 10 survive the expiration, cancellation, suspension, revocation, or termination of the User’s account, subscription, license, access rights, or applicable agreement. These Sections continue to apply to data, output, content, software, documentation, Confidential, Information, credentials, copies, extracts, datasets, models, derivative materials, or other items accessed, collected, obtained, generated, created, retained, or disclosed before expiration, cancellation, suspension, revocation, or termination.